An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because access control is implemented on the client side via a disabled attribute for a BUTTON element.
2018-12-26T21:29:02.230
2024-11-21T03:58:17.493
Modified
CVSSv3.0: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | rockwellautomation | powermonitor_1000_firmware | 1408-em3a-ent_b | Yes |
| Hardware | rockwellautomation | powermonitor_1000 | - | No |